All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eric Biggers <ebiggers@kernel.org>
To: Nathan Huckleberry <nhuck@google.com>
Cc: linux-crypto@vger.kernel.org, linux-fscrypt@vger.kernel.org,
	Herbert Xu <herbert@gondor.apana.org.au>,
	"David S. Miller" <davem@davemloft.net>,
	linux-arm-kernel@lists.infradead.org,
	Paul Crowley <paulcrowley@google.com>,
	Sami Tolvanen <samitolvanen@google.com>,
	Ard Biesheuvel <ardb@kernel.org>
Subject: Re: [PATCH v7 8/9] crypto: arm64/polyval: Add PMULL accelerated implementation of POLYVAL
Date: Mon, 9 May 2022 14:41:45 -0700	[thread overview]
Message-ID: <YnmKmfYbYahvYnrF@sol.localdomain> (raw)
In-Reply-To: <20220509191107.3556468-9-nhuck@google.com>

On Mon, May 09, 2022 at 07:11:06PM +0000, Nathan Huckleberry wrote:
> Add hardware accelerated version of POLYVAL for ARM64 CPUs with
> Crypto Extensions support.
> 
> This implementation is accelerated using PMULL instructions to perform
> the finite field computations.  For added efficiency, 8 blocks of the
> message are processed simultaneously by precomputing the first 8
> powers of the key.
> 
> Karatsuba multiplication is used instead of Schoolbook multiplication
> because it was found to be slightly faster on ARM64 CPUs.  Montgomery
> reduction must be used instead of Barrett reduction due to the
> difference in modulus between POLYVAL's field and other finite fields.
> 
> More information on POLYVAL can be found in the HCTR2 paper:
> "Length-preserving encryption with HCTR2":
> https://eprint.iacr.org/2021/1441.pdf
> 
> Signed-off-by: Nathan Huckleberry <nhuck@google.com>
> Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
> ---
>  arch/arm64/crypto/Kconfig           |   5 +
>  arch/arm64/crypto/Makefile          |   3 +
>  arch/arm64/crypto/polyval-ce-core.S | 361 ++++++++++++++++++++++++++++
>  arch/arm64/crypto/polyval-ce-glue.c | 193 +++++++++++++++
>  4 files changed, 562 insertions(+)
>  create mode 100644 arch/arm64/crypto/polyval-ce-core.S
>  create mode 100644 arch/arm64/crypto/polyval-ce-glue.c

Reviewed-by: Eric Biggers <ebiggers@google.com>

- Eric

WARNING: multiple messages have this Message-ID (diff)
From: Eric Biggers <ebiggers@kernel.org>
To: Nathan Huckleberry <nhuck@google.com>
Cc: linux-crypto@vger.kernel.org, linux-fscrypt@vger.kernel.org,
	Herbert Xu <herbert@gondor.apana.org.au>,
	"David S. Miller" <davem@davemloft.net>,
	linux-arm-kernel@lists.infradead.org,
	Paul Crowley <paulcrowley@google.com>,
	Sami Tolvanen <samitolvanen@google.com>,
	Ard Biesheuvel <ardb@kernel.org>
Subject: Re: [PATCH v7 8/9] crypto: arm64/polyval: Add PMULL accelerated implementation of POLYVAL
Date: Mon, 9 May 2022 14:41:45 -0700	[thread overview]
Message-ID: <YnmKmfYbYahvYnrF@sol.localdomain> (raw)
In-Reply-To: <20220509191107.3556468-9-nhuck@google.com>

On Mon, May 09, 2022 at 07:11:06PM +0000, Nathan Huckleberry wrote:
> Add hardware accelerated version of POLYVAL for ARM64 CPUs with
> Crypto Extensions support.
> 
> This implementation is accelerated using PMULL instructions to perform
> the finite field computations.  For added efficiency, 8 blocks of the
> message are processed simultaneously by precomputing the first 8
> powers of the key.
> 
> Karatsuba multiplication is used instead of Schoolbook multiplication
> because it was found to be slightly faster on ARM64 CPUs.  Montgomery
> reduction must be used instead of Barrett reduction due to the
> difference in modulus between POLYVAL's field and other finite fields.
> 
> More information on POLYVAL can be found in the HCTR2 paper:
> "Length-preserving encryption with HCTR2":
> https://eprint.iacr.org/2021/1441.pdf
> 
> Signed-off-by: Nathan Huckleberry <nhuck@google.com>
> Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
> ---
>  arch/arm64/crypto/Kconfig           |   5 +
>  arch/arm64/crypto/Makefile          |   3 +
>  arch/arm64/crypto/polyval-ce-core.S | 361 ++++++++++++++++++++++++++++
>  arch/arm64/crypto/polyval-ce-glue.c | 193 +++++++++++++++
>  4 files changed, 562 insertions(+)
>  create mode 100644 arch/arm64/crypto/polyval-ce-core.S
>  create mode 100644 arch/arm64/crypto/polyval-ce-glue.c

Reviewed-by: Eric Biggers <ebiggers@google.com>

- Eric

_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel

  reply	other threads:[~2022-05-09 21:41 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-05-09 19:10 [PATCH v7 0/9] crypto: HCTR2 support Nathan Huckleberry
2022-05-09 19:10 ` Nathan Huckleberry
2022-05-09 19:10 ` [PATCH v7 1/9] crypto: xctr - Add XCTR support Nathan Huckleberry
2022-05-09 19:10   ` Nathan Huckleberry
2022-05-09 19:11 ` [PATCH v7 2/9] crypto: polyval - Add POLYVAL support Nathan Huckleberry
2022-05-09 19:11   ` Nathan Huckleberry
2022-05-09 19:11 ` [PATCH v7 3/9] crypto: hctr2 - Add HCTR2 support Nathan Huckleberry
2022-05-09 19:11   ` Nathan Huckleberry
2022-05-09 19:11 ` [PATCH v7 4/9] crypto: x86/aesni-xctr: Add accelerated implementation of XCTR Nathan Huckleberry
2022-05-09 19:11   ` Nathan Huckleberry
2022-05-09 19:11 ` [PATCH v7 5/9] crypto: arm64/aes-xctr: " Nathan Huckleberry
2022-05-09 19:11   ` Nathan Huckleberry
2022-05-09 19:11 ` [PATCH v7 6/9] crypto: arm64/aes-xctr: Improve readability of XCTR and CTR modes Nathan Huckleberry
2022-05-09 19:11   ` Nathan Huckleberry
2022-05-09 21:56   ` Eric Biggers
2022-05-09 21:56     ` Eric Biggers
2022-05-09 19:11 ` [PATCH v7 7/9] crypto: x86/polyval: Add PCLMULQDQ accelerated implementation of POLYVAL Nathan Huckleberry
2022-05-09 19:11   ` Nathan Huckleberry
2022-05-09 21:44   ` Eric Biggers
2022-05-09 21:44     ` Eric Biggers
2022-05-09 19:11 ` [PATCH v7 8/9] crypto: arm64/polyval: Add PMULL " Nathan Huckleberry
2022-05-09 19:11   ` Nathan Huckleberry
2022-05-09 21:41   ` Eric Biggers [this message]
2022-05-09 21:41     ` Eric Biggers
2022-05-09 19:11 ` [PATCH v7 9/9] fscrypt: Add HCTR2 support for filename encryption Nathan Huckleberry
2022-05-09 19:11   ` Nathan Huckleberry

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=YnmKmfYbYahvYnrF@sol.localdomain \
    --to=ebiggers@kernel.org \
    --cc=ardb@kernel.org \
    --cc=davem@davemloft.net \
    --cc=herbert@gondor.apana.org.au \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-fscrypt@vger.kernel.org \
    --cc=nhuck@google.com \
    --cc=paulcrowley@google.com \
    --cc=samitolvanen@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.